AnchorMark
Industry

Capture defects without capturing PII.

Auto-redaction for sensitive inputs, immutable audit logs, and SSO/SCIM for the access controls your auditor expects.

Talk to sales

What hurts today

  • Sensitive form data must never leave the client.
  • Auditors expect immutable logs of every privileged action.
  • Identity provider must be the source of truth for access.
  • Vendor risk reviews stall when the feedback tool can't produce a DPA or sub-processor list on demand.

How AnchorMark fits

Field-level redaction

Marked inputs are blurred in screenshots and stripped from console payloads.

Immutable audit log

Every privileged write recorded with API export to your SIEM.

SSO and SCIM

WorkOS-powered identity with group-derived role assignment.

Documented vendor posture

Public sub-processor list, a DPA on request, and a tenant-isolation smoke test that runs in CI.

Compliance note

A current DPA is available for execution; sub-processors are listed publicly.

Frequently asked questions

Where is data stored?
Currently US and EU regions; per-region data residency at the project level is on the roadmap. EU-region storage is available today for European customers.
Can I require SSO for all members?
Yes — Enterprise workspaces can enforce SSO and disable password login. SCIM keeps user and group state in sync with your IdP via SSO & SCIM.
How do you keep PII out of screenshots?
Mark inputs with data-anchormark="redact" and the SDK blurs them in the captured frame and strips them from console payloads. Workspace-wide redaction rules apply policy without per-page configuration — see security & compliance.
Do you have SOC 2?
AnchorMark is on a SOC 2 Type II path; current attestation status and the sub-processor list are kept up to date on the security page.
Can I export the audit log to my SIEM?
Yes. The audit log streams to S3 or any HTTPS endpoint via the webhooks API. Splunk, Datadog, and Panther are commonly used downstream.
Do you sign a DPA?
Yes — a DPA summary is published on the DPA page and the full executable version is available on request.
How fast does deactivation propagate when an employee leaves?
SCIM deactivation suspends the user and terminates active sessions within seconds. Every termination is recorded in the audit log.

Bring AnchorMark to your fintech team.

Free 14-day trial — no credit card required.

Compare plans